Sceawere
Vulnerability Detail
CVE-2026-94681UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Store Locator Unauthenticated DoS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 3h ago
- Vendor
- Tijmen Smit
- Product
- WP Store Locator
- Attack Type
- CWE-770 Allocation of Resources Without Limits or Throttling
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-09-30T13:17:27.810Z",
"pubdate": "2026-09-30T13:17:27.810Z",
"executiveSummary": "WP Store Locator versions prior to 3.0.0 contain a vulnerability that facilitates an unauthenticated Denial of Service (DoS) attack.\nThis vulnerability stems from improper input validation or resource management within the plugin's request handling mechanisms, allowing remote attackers to exhaust server resources.\nThe primary impact of this flaw is the potential for service disruption, rendering the affected WordPress instance or the specific store locator functionality unresponsive to legitimate user requests.\nThe vulnerability is exploitable by unauthenticated attackers over a network, requiring no specific privileges or user interaction to initiate the attack.\nThe risk implication is high for site availability, as attackers can induce system instability or significant latency through high-frequency requests targeting the vulnerable endpoint.\nImmediate remediation involves upgrading the plugin to version 3.0.0 or later to ensure the implementation of necessary request throttling and input sanitization controls.",
"technicalDetails": "The vulnerability resides in the request processing logic of the WP Store Locator plugin prior to version 3.0.0, specifically impacting how the plugin handles inbound API requests or store location queries.\nThe root cause is a failure to implement rate limiting, request validation, or resource exhaustion protections on public-facing endpoints. This design flaw allows an attacker to send a high volume of crafted, computationally expensive requests to the server without authentication.\nExploitation involves an attacker identifying the endpoint responsible for querying the store database. By repeatedly triggering this functionality with parameters designed to maximize resource consumption—such as complex geographic search radii or malformed inputs that cause recursion or inefficient database table scans—the attacker forces the web server to allocate disproportionate CPU and memory resources.\nThe attack flow follows a straightforward progression: 1) The attacker maps the target WP Store Locator endpoint. 2) The attacker issues a series of automated HTTP GET or POST requests designed to bypass existing limitations or exploit inefficient handling of location-based search operations. 3) The target server enters a state of resource saturation, resulting in high load averages and degraded performance for legitimate users. 4) Continuous exploitation leads to a complete failure of the plugin's service or the underlying web server process, manifesting as a Denial of Service.\nBecause the vulnerability is unauthenticated, it is accessible via standard HTTP protocols across any network with access to the WordPress site. The plugin lacks the necessary internal checks to distinguish between routine queries and malicious, resource-depleting traffic, effectively turning the plugin's core search functionality into an attack vector.\nPost-exploitation impact includes the total loss of availability for the store locator feature, increased server-side log volume that may obscure further malicious activity, and potential secondary impacts on shared hosting environments where resource exhaustion affects adjacent services or other websites hosted on the same server instance. The flaw does not necessarily grant administrative access or execute arbitrary code but fundamentally compromises the operational integrity of the site."
}